arjanver Posted September 13, 2018 Posted September 13, 2018 Well for what it's worth we're having this issue and we're using GPO deployed printers (through print management). I'm at the point of despair where I'm going to upgrade the print server from 2012r2 to 2016 and hope for the best. I've always despised the concept of deploying printers with scripts (idk, I guess I feel like it shouldn't be necessary ), but it looks like we could be heading that way.. ugh.We had server 2008 dc's and 2012 printserver and Windows 10 clients and we have migrated everything to server 2016 but the problem still exists. So to me it is a Windows 10 bug. Well Windows 10 to me is the new Windows ME.
eddyc Posted September 13, 2018 Posted September 13, 2018 We had server 2008 dc's and 2012 printserver and Windows 10 clients and we have migrated everything to server 2016 but the problem still exists. So to me it is a Windows 10 bug. Well Windows 10 to me is the new Windows ME. Yes I agree it’s Windows 10 related. We have a 2016 print server and it doesn’t seem to have helped at all. We had the same issue at around the same level when we had our previous 2012 r2 print server too
revilo Posted September 25, 2018 Posted September 25, 2018 Brand new 2016 print server here with brand new Konica MFD's and PaperCut Windows 10 LTSB 2016 clients, running roaming profiles for staff and mandatory profiles for students. Printers appear when they feel like it, tend to be better (but not perfect) once a profile has been loaded onto the machine. Driving me mad!!
Popular Post Arthur Posted September 25, 2018 Popular Post Posted September 25, 2018 Brand new 2016 print server here with brand new Konica MFD's and PaperCut Windows 10 LTSB 2016 clients, running roaming profiles for staff and mandatory profiles for students. I'm not sure if it will help but I have documented all of my print-related settings below. Printing works perfectly for everyone at my school (I hope I haven't jinxed it now!) Environment Windows 10 v1703 clients + brand new Windows Server 2016 gen. 2 VM with PaperCut MF 18.2 and brand new Ricoh/Kyocera copiers & drivers All users have local profiles with folder redirection for everything apart from AppData (which is kept local). Settings are synced with UE-V. Printers are mapped via a user-based GPP with the Mono print queue being set as the default. User-based Group Policies User Configuration > Administrative Templates > Control Panel > Printers [b]Turn off Windows default printer management[/b] = Enabled User Configuration > Administrative Templates > System > Logon [b]Run these programs at user logon[/b] = Enabled Items to run at logon: "C:\Program Files (x86)\PaperCut MF Client\pc-client.exe" Computer-based Group Policies Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment [b]Load and unload device drivers[/b]: BUILTIN\Users Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options [b]Devices: Prevent users from installing printer drivers[/b] = Disabled Computer Configuration > Administrative Templates > System > Driver Installation [b]Allow non-administrators to install drivers for these device setup classes[/b] [url=https://docs.microsoft.com/en-us/windows-hardware/drivers/install/system-defined-device-setup-classes-available-to-vendors]{4d36e979-e325-11ce-bfc1-08002be10318}[/url] Computer Configuration > Administrative Templates > Printers [b]Package Point and print - Approved servers[/b] = Enabled FQDN(s) of your print server(s) (e.g. print-01.example.net) [b]Point and Print Restrictions[/b] = Enabled [b]Users can only point and print to these servers[/b]: FQDN(s) of your print server(s) (e.g. print-01.example.net) Security Prompts: [b]When installing drivers for a new connection[/b]: Do not show warning or elevation prompt [b]When updating drivers for an existing connection[/b]: Do not show warning or elevation prompt 6
Sheridan Posted September 25, 2018 Posted September 25, 2018 I've been working with the broken W10 printing environment for over a year now and although using preferences and item level targeting has had the best results its still unreliable. It's also very inconsistent, as many users will login and not see their printer in the Printers control panel app (in either of the control panels!) but it will appear in Word or Chrome for example!
arjanver Posted September 25, 2018 Posted September 25, 2018 Anyone tested on Windows 10 1803? As in An 1803 cu update changelog looks it says something about this issue?
eddyc Posted September 26, 2018 Posted September 26, 2018 Anyone tested on Windows 10 1803? As in An 1803 cu update changelog looks it says something about this issue? Our whole site is fully patched 1803 but the issue is still just as bad for us.
Sheridan Posted September 26, 2018 Posted September 26, 2018 Anyone tested on Windows 10 1803? As in An 1803 cu update changelog looks it says something about this issue? Does anyone have faith in what the changelog says these days! I gave up reading it a few releases ago
Arthur Posted September 26, 2018 Posted September 26, 2018 Anyone tested on Windows 10 1803? Our whole site is fully patched 1803 but the issue is still just as bad for us. I've been working with the broken W10 printing environment for over a year now and although using preferences and item level targeting has had the best results its still unreliable. Just to add to my previous post. Most our the PCs are running 1703, although the ones that have been upgraded to 1803 are also working perfectly.
arjanver Posted September 26, 2018 Posted September 26, 2018 okay, so you don't have printing problems Arthur? I have all of these policies active except those 2: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights AssignmentLoad and unload device drivers: BUILTIN\Users Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security OptionsDevices: Prevent users from installing printer drivers = Disabled
Driftingashore Posted September 26, 2018 Posted September 26, 2018 I don't have those two policies set either (though also have point and print disabled, and we use roaming profiles). I've just set: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security OptionsDevices: Prevent users from installing printer drivers = Disabled One change at a time an all that. We'll see how it goes, though I think people have given up reporting missing printers, so I suspect I'll have to do some testing when I'm feeling inspired.
Arthur Posted September 26, 2018 Posted September 26, 2018 (edited) okay, so you don't have printing problems? None that I am aware of. Our teachers are very vocal when it comes to printing so I would have known about any issues by now. I have all of these policies active except those 2: How up-to-date are your print drivers? I'm not sure if it makes any difference to printing, but I also have SMB1 disabled on all clients and servers. Edited September 26, 2018 by Arthur
dfergusson Posted September 26, 2018 Posted September 26, 2018 This policy is disabled by default on Workstations. Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security OptionsDevices: Prevent users from installing printer drivers = Disabled
dfergusson Posted September 26, 2018 Posted September 26, 2018 I'm not sure if it will help but I have documented all of my print-related settings below. Printing works perfectly for everyone at my school (I hope I haven't jinxed it now!) Settings are synced with UE-V. Arthur are you also syncing Network Printers as part of your UE-V Windows Settings?
Arthur Posted September 26, 2018 Posted September 26, 2018 are you also syncing Network Printers as part of your UE-V Windows Settings? No. We have a follow me printing system so there hasn't been any need to sync network printers through UE-V.
eddyc Posted September 27, 2018 Posted September 27, 2018 I'm not sure if it will help but I have documented all of my print-related settings below. Printing works perfectly for everyone at my school (I hope I haven't jinxed it now!) Environment Windows 10 v1703 clients + brand new Windows Server 2016 gen. 2 VM with PaperCut MF 18.2 and brand new Ricoh/Kyocera copiers & drivers All users have local profiles with folder redirection for everything apart from AppData (which is kept local). Settings are synced with UE-V. Printers are mapped via a user-based GPP with the Mono print queue being set as the default. User-based Group Policies User Configuration > Administrative Templates > Control Panel > Printers [b]Turn off Windows default printer management[/b] = Enabled User Configuration > Administrative Templates > System > Logon [b]Run these programs at user logon[/b] = Enabled Items to run at logon: "C:\Program Files (x86)\PaperCut MF Client\pc-client.exe" Computer-based Group Policies Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment [b]Load and unload device drivers[/b]: BUILTIN\Users Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options [b]Devices: Prevent users from installing printer drivers[/b] = Disabled Computer Configuration > Administrative Templates > System > Driver Installation [b]Allow non-administrators to install drivers for these device setup classes[/b] [url=https://docs.microsoft.com/en-us/windows-hardware/drivers/install/system-defined-device-setup-classes-available-to-vendors]{4d36e979-e325-11ce-bfc1-08002be10318}[/url] Computer Configuration > Administrative Templates > Printers [b]Package Point and print - Approved servers[/b] = Enabled FQDN(s) of your print server(s) (e.g. print-01.example.net) [b]Point and Print Restrictions[/b] = Enabled [b]Users can only point and print to these servers[/b]: FQDN(s) of your print server(s) (e.g. print-01.example.net) Security Prompts: [b]When installing drivers for a new connection[/b]: Do not show warning or elevation prompt [b]When updating drivers for an existing connection[/b]: Do not show warning or elevation prompt I've just added the two missing bits here - BULTIN\Users and the driver installation GPO, that aside we were like, for like. Heres to hoping that it fixes it for us. Cheers Arthur
Arthur Posted September 27, 2018 Posted September 27, 2018 Heres to hoping that it fixes it for us. Let's hope so. [emoji846]
arjanver Posted September 27, 2018 Posted September 27, 2018 Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security OptionsDevices: Prevent users from installing printer drivers = Disabled When reading info on this gpo is says it's disabled nu default on workstations and enabled on servers. So it looks to me it is not gona solve the problem.
IrritableTech Posted October 2, 2018 Posted October 2, 2018 We’ve been having problems this year since moving to w10 with printers not loading. To finally crack the issue we’ve ended up changing from a login script to a startup script in the start menu. This seems far far more reliable. Seems a little old fashioned, but it’s made the difference so it’ll do for me!
Sheridan Posted October 2, 2018 Posted October 2, 2018 I'm thinking about reverting to scripts or something similar. Its so unpredictable - brand new ICT Suite with 30 computers in (identical hardware and image) - 30 students login (identical policy settings) and 24 got the printer, 2 got the printer after 10 minutes and the other 4 had to logoff and back to see the printers. Its really annoying, and I feel for the teachers in the rooms, but as ICT support we're stuck with this POS until MS rewrite 10 again.
rosslaing Posted October 2, 2018 Posted October 2, 2018 We also moved to Startup scripts in the start menu rather than login scripts when we went to 1703 from 1511. Much more reliable and it also takes a chunk out the login times, seeing as it starts to map the printers once the user is actually at a desktop. It is still not 100% but we also have a shortcut to the script in the start menu that users can click on if for some reason the printers have not mapped.
Sheridan Posted October 2, 2018 Posted October 2, 2018 We also moved to Startup scripts in the start menu rather than login scripts when we went to 1703 from 1511. Much more reliable and it also takes a chunk out the login times, seeing as it starts to map the printers once the user is actually at a desktop. It is still not 100% but we also have a shortcut to the script in the start menu that users can click on if for some reason the printers have not mapped. Out of curiosity how are you mapping the printers in your login scripts? Are you using the PrintUIEntry method?
rosslaing Posted October 2, 2018 Posted October 2, 2018 (edited) Out of curiosity how are you mapping the printers in your login scripts? Are you using the PrintUIEntry method? We have a Batch file which then calls a powershell script. We are trying to use Powershell for everything these days seeing as this is the main, built in supported scripting language. We need the batch file to bypass the powershell restrictions temporarily to allow the powershell script to run seeing as it is run in the users context. The batch file calls the powershell script which does a bit of info gathering to discover the AD site the machine is located in, then that powershell script calls another Powershell script for that school. The individual schools script determines which OU the machine is in and maps printers accordingly. Edited October 2, 2018 by rosslaing 2
Garacesh Posted October 2, 2018 Posted October 2, 2018 (edited) We have a Batch file which then calls a powershell script. We are trying to use Powershell for everything these days seeing as this is the main, built in supported scripting language. We need the batch file to bypass the powershell restrictions temporarily to allow the powershell script to run seeing as it is run in the users context. Can't you just run the script with -ExecutionPolicy Bypass? Or just sign it? I can't imagine a scenario where you could run the script via cmd as a standard user that wouldn't work by just firing up the script? I'm curious as to your process/what the batch file actually does? Edited October 2, 2018 by Garacesh
rosslaing Posted October 2, 2018 Posted October 2, 2018 (edited) Can't you just run the script with -ExecutionPolicy Bypass? Or just sign it? I can't imagine a scenario where you could run the script via cmd as a standard user that wouldn't work by just firing up the script? I'm curious as to your process/what the batch file actually does? Thats what the batch file does, -executionpolicy bypass, At some point we will be looking into signing the scripts but with everything else that goes on its finding the time! The default execution policy does not allow users to run PS scripts and I dont intend changing that for obvious reasons. If you were to run it as a Logon script then it doesnt matter the PS scripts will run no problem, but then you are waiting on printers adding as part of the login. @echo off powershell.exe -ExecutionPolicy Bypass -windowstyle hidden -noninteractive -nologo -file "\\domain\netlogon\PrinterScripts\Add-Printers.ps1" Edited October 2, 2018 by rosslaing
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now